{"slug": "ai-escape-incident-tracker", "title": "AI Escape Incident Tracker", "summary": "A new public database, the AI Escape Incident Tracker, catalogs failures of AI control systems rather than harms, recording the assigned task of each autonomous agent at the time of a breach. The tracker, published as a draft, assigns each incident a Containment Breach Score (CBS v0.1) from 0 to 10 based on six weighted factors, and groups entries by month, with a cluster in mid-2026 representing one continuous event fragmented across four disclosures. Entries are reviewed by a human reviewer before publication, and the tracker links each incident to guardrail classes that were absent or ineffective.", "body_md": "Existing databases index AI **harms**. This one indexes the control that failed —\n          and what each agent was actually deployed to do when it crossed the line. Because in\n          **— of —** entries here, the agent\n          was doing exactly the job it was given.\n        \n\nEvery entry placed at the month it occurred, sized by Containment Breach Score. The cluster in mid-2026 is one continuous event that fragmented across four separate disclosures. Select a marker to open its entry.\n\nEvery incident links to each guardrail class that was absent or ineffective. Controls that many incidents share pull to the centre — those are the ones worth funding first. Hover to isolate a node, select an incident to open its entry.\n\nGrouped by month of occurrence, newest first. Every entry records the agent's assigned task alongside the failure — the task is usually the more revealing of the two. Figures that disagree across reports are marked disputed rather than averaged.\n\nSeven stages, drawn from how the 2026 events actually unfolded. Unlike an attacker kill chain it begins *inside* the system, at the pressure that made boundary-seeking the higher-scoring move.\n\nPRESSURE · PROBE · BREACH · CHANNEL · ESCALATE · PROPAGATE · HALT\n\nCVSS scores a vulnerability. CBS v0.1 scores how far an autonomous system got and how long nobody noticed — six weighted factors, 0–10.\n\nPublished as a draft, meant to be argued with.\n\nThe reason to index by control rather than by harm: the pattern becomes legible.\n\nRegistry entries in which each control was absent or ineffective (n = —). Entries name more than one, so counts sum above n.\n\nA registry is only as good as the record behind it. These are the parties holding primary material on the entries above — post-mortems, packet captures, edit histories, evaluation logs — and what each one actually has. Where a claim in the registry rests on one of these, the entry cites it.\n\n| Tracker | Kind | Holds | Entries | Checked | \n|---|---|---|---|---|\n\nTwo fields are required. A reviewer checks the sources, grades the entry, and publishes it — nothing reaches the registry unreviewed. Do not submit credentials, customer data, or anything under embargo: the review queue is visible to every reader.", "url": "https://wpnews.pro/news/ai-escape-incident-tracker", "canonical_source": "https://ai-escape.watch/#registry", "published_at": "2026-09-07 07:05:25+00:00", "updated_at": "2026-09-07 07:27:21.132477+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy"], "entities": ["AI Escape Incident Tracker"], "alternates": {"html": "https://wpnews.pro/news/ai-escape-incident-tracker", "markdown": "https://wpnews.pro/news/ai-escape-incident-tracker.md", "text": "https://wpnews.pro/news/ai-escape-incident-tracker.txt", "jsonld": "https://wpnews.pro/news/ai-escape-incident-tracker.jsonld"}}